During my work at the Computer Reliability Research Laboratory, we wrote one paper on our "honeypots" research under the direction of Dr. Michel Cukier:

Cladek, W. and Schoenbrun, J. (2006). Evaluating Data Collection Tools for Improving Attack Analysis.

It was not published, but served as the basis for a paper by the undergraduates who took over my research at that research lab:

Molina, J. and Gordon, J. (2007). An Empirical Study of Filesystem Activity Following a SSH Compromise. In 6th International Conference on Information, Communications & Signal Processing, pages 1–5.

Yiḥezkel Jason Schoenbrun,
Oct 8, 2010, 11:52 AM